Agenda item

To present to the Committee the progress on outstanding actions identified by the Committee along with general updates on other issues that fall within the responsibilities of the Committee.

Minutes:

Members were aware that a Table of Outstanding Issues was maintained and reported to each meeting of the Committee. This approach enabled the Committee to effectively monitor progress on issues and items that form part of its governance responsibilities.

 

It was reported that, given the relatively short period of time since the last update had been presented to the Committee on 19 February 2026, there had been no major updates against the general items, the Annual Governance Statement or External Audit recommendations that had usually been set out within the associated appendices. Therefore, those appendices had not been repeated within this report (A.2). However, work remained ongoing against all outstanding actions with timely information set out in the A.2 report where necessary.

 

In terms of the Annual Governance Statement Actions that had been regularly reported to the Committee, there were no required changes emerging from the recent external audit process, with the various activities having remained unchanged. Existing actions had therefore remained in progress with no major issues to raise at that time, with the usual and more detailed update planned to be presented to the Committee at its meeting that was currently programmed for June 2026.

 

The Committee heard that the review of the effectiveness of the Audit Committee was a key action included within the current Annual Governance Statement Action Plan and as planned, a review had been undertaken that had included both Officers and Members of the Committee, with the latest facilitated session held with Members on 5 March 2026.

 

The outcome of that work was currently being reviewed / collated and it was planned to present a summary of the outcomes along with an associated action plan to the June 2026 meeting of the Committee.

 

It was reported that similarly, the risk management review was also a key action included within the current Annual Governance Statement Plan.

 

Associated activities that had been undertaken to date, involving both Officers and Members had included:

1)    Training had been provided in terms of the Role of the Audit Committee that had been delivered by an external specialist trainer in January 2025.

2)    More targeting training had been delivered by an external specialist trainer in January 2026 based on challenging and revieing the Council’s current Corporate Risk Framework, register and approach.

3)    Following on from 2) above, a facilitated session had been held with Members on 5 March 2026 to review and consider potential changes to the Council’s approach.

 

It was highlighted that the training outlined in point 2) had covered a number of key areas including:

·         Benefits and characteristics of effective risk management

·         Audit Committee and other Members role in risk management

·         Risk registers

·         Appetite and tolerance

·         Assurance and challenge

·         Re-framing risk management

 

It was further reported that the session had also identified the characteristics of effective risk management along with a high-level view of what an assurance risk framework should ideally include, which was summarised as follows:

 

Financial Management

Legislative Compliance

Workforce Management / HR

Decision Making

Information Systems Management

Health & Safety

Information Governance and Compliance

Business Continuity and ER

Performance Management and Data

Ethical Standards and Conduct Management

Procurement and Contract Management

Equalities and Inclusion

Project and Programme Management

Risk Mgt / Gov. Assurance

Partnership and Collaboration Governance

Compliance with IA, Ext Audit and Inspections etc.

 

All of the above elements had been reviewed and considered at the facilitated session held on 5 March 2026 within the following context:

 

Key Background / Issue

Current Position / Comments

What do we do already?

We already have in place and actively apply:

 

A Code of Corporate Governance

 

An Annual Governance Statement and Review

 

Performance Management Reporting

 

Corporate Risk Register and Framework

 

Departmental Risk Registers

 

Other risk / governance reviews and activities

 

Internal and External Audit Inspection and Reviews. (In terms of External Audit, they concluded that the Council had effective risk management arrangements in place and there were no significant overall governance weaknesses identified within their recent VFM review)

 

Out risk appetite

Treat, tolerate not terminate

Assurance frameworks v risk frameworks

They ask different questions and capture different things e.g.

 

RISK – Strategic risks are those risks that could materially affect a local council’s ability to function effectively, achieve its statutory duties and strategic objectives, or maintain financial sustainability, governance, and public confidence.

 

ASSURANCE - What arrangements do we rely on to ensure success, delivery, performance and compliance.

 

Risks concentrate on things going wrong / failures, where assurance focuses on a positive approach of what needs to be in place etc. to ensure / provide assurance across the issues identified within the earlier table above.

 

Using financial sustainability as an example:

 

RISK APPROACH - There is a risk that the Council does not have sufficient funding or resources to deliver its priorities, leading to service failure and financial instability.

 

ASSURANCE APPROACH - The Council has effective financial management, medium?term financial planning, budget monitoring and governance arrangements in place to ensure it can deliver its priorities and remain financially sustainable within available resources

 

What Management / Members would therefore need to seek assurance on would include:

       MTFS exists, is up to date, and is stress?tested

       Budget monitoring is timely and acted upon

       Reserves strategy is clear and aligned to risk appetite

       Statutory officer oversight (s151) is effective

 

What do other Local Authorities do and what is promoted by relevant organisations within the risk management and assurance sectors?

 

Evidence suggests that many authorities take a traditional approach adopting the same as the Council in terms of identifying key risks, scoring them and how the Council is responding with inherent and residual risks highlighted. It is also fair to say that this approach aligns with many aspects of advice / guidance from sector experts. 

 

However, it is noted that a limited number of Council’s are adopting a comprehensive Assurance Framework and ‘translating’ a number of their existing risks alongside other assurance elements into a fully revised assurance focused approach.

 

 

it was reported that, in taking the review forward and reflecting on the challenge raised during the training session held in January 2026, a number of key issues were being considered, together with the wider context for developing the Council’s future approach.

 

·         It was noted that the Council already had several important components in place, although there were opportunities to bring these together in a more coherent and accessible framework.

·         Members were advised that there were timely opportunities to adopt a stronger assurance?based approach, potentially through a hybrid model. This could also serve as a useful framework in the context of establishing the new Unitary Council, recognising that governance disciplines such as assurance and risk management significantly influence organisational culture, including that of the successor authority.

·         The Committee was encouraged to reflect on the distinction between strategic risks and those more appropriately captured at a corporate or departmental level. In doing so, reference was made to the high?level definition of a strategic risk as one where failure would materially impair the organisation’s ability to function or deliver its purpose.

·         It was acknowledged that there remained value in retaining a form of risk scoring, although this might be more effectively delivered through a traffic?light system rather than a numerical model.

·         The importance of balancing capacity, resources and overall effectiveness was emphasised, including the need for engagement from both Officers and Members. Any revised approach should complement existing processes rather than introduce unnecessary additional layers of work or bureaucracy.

 

Taking these factors into account, the initial outcomes from the facilitated session held with Members on 5 March 2026 had highlighted several key elements to be taken forward, with the aim of achieving a balanced and effective governance framework.

 

The Committee noted that the following chart, that had been included within the report (A.2) illustrated the proposed underlying structure and approach for further development:

 

 

It was highlighted that Officers intended to develop the approach further, with the aim of presenting the proposed revised assurance and risk management framework to the Committee at its next meeting in June. It was noted that this work might include additional facilitated sessions with Officers and Members during the interim period to support timely implementation and ensure the revised approach was embedded as early as possible in 2026/27.

 

It was acknowledged that the Committee had not received a full risk register report since January 2025, although interim updates had been provided in September 2025 where necessary. Officers emphasised the importance of assuring the Committee that a range of underlying risk?management activities continued to operate effectively within existing governance arrangements. Those activities were also being supplemented by additional work, including:

·         The review of departmental risks as part of the Directorate and Service Planning process, supported by Management Team reinforcing the importance of risk management at both operational and corporate levels.

·         The monthly reporting of associated risks to the Regeneration and Capital Delivery Board.

·         The establishment of the Senior Officer Project Board in the previous year, as referenced in the Annual Governance Statement.

 

Within this context, Officers confirmed that there were no major issues requiring the Committee’s attention at the present time. However, it was considered important to highlight the four current residual risks rated as ‘red’, as follows:

 

Risk

Status / Comments / Update

RISK 1d - Ineffective Cyber Security Physical and Application (software) Based Protection Management

 

The network infrastructure hardware was replaced during 2025 and has a realistic end-of-life longevity of 5-7 years (2030 – 2032). The Cloud Infrastructure provides significantly enhanced resilience / recovery capabilities in terms of hardware failure. Remote working capabilities provides key business continuity and service delivery options if / when key office locations are unavailable. Cyber-security arrangements include 24/7 network visibility, monitoring, reporting and alarms together with a 24/7 Security Operations Centre (SOC) provided by a 3rd party – all facilitating both reactive and pro-active response. The greatest cyber-security protection is afforded by the Council’s adoption of managed-device only access to services with zero-trust real-time monitoring of devices for vulnerabilities. Cyber-security is robust but it is recognised that any breach could be significant in terms of service loss and / or data theft.

 

RISK 2a - Coastal Defence

 

Associated risks continue to be mitigated via conducting annual inspections of coast protection structures and responding swiftly to public reporting of minor faults. An annual maintenance programme for the coastal frontage is set each year, supported by associated surveys as necessary, with an appropriate budget to cover the works (one-off funding of £2m was set aside to support such works). Each year sections of the sea defences are also improved as part of a rolling programme of special maintenance schemes funded from an on-going revenue budget.

 

RISK 5A - Financial Strategy

 

A robust and sustainable two -year financial plan was agreed by Full Council in February 2026. This included ‘cash-backed’ investment and responses to a number of financial challenges along with setting out an in-principle / notional approach to meeting obligations to a new Unitary Council from as early as 1 April 2028.

 

RISK 6a - Loss of sensitive and/or personal data through malicious actions loss theft and/or hacking.

 

As Data Controller, the Council has a legislative duty to evidence and ensure that information is managed / protected in compliance with legislation and protected against unauthorised or unlawful processing and against accidental loss / destruction / damage through using appropriate security. The Council achieves this and mitigates risk of data-breach by: mandatory Data Protection and Cyber Security training, working collaboratively with other local authorities sharing best practices and aligning policies and procedures and ensure consistent governance, improving information governance systems,  maintaining a Records of Processing Activities [ROPA], improvements to Security Incident Reporting systems, improving information governance guidance for staff through improved intranet pages, having robust data sharing agreements where partner organisations are managing data on behalf of the Council.

 

All of the above, together with robust cyber-security, mitigate this risk, as far as reasonably possible, to the organisation.

 

 

It was noted that, where possible, the Committee was normally presented with the External Auditor’s Audit Plan and Strategy for the forthcoming year. Following discussions with the External Auditor, it was now proposed that this be brought to the Committee’s June meeting. Officers confirmed that there were no significant implications arising from this revised timetable, as the Committee would still receive the plan of the more detailed work and subsequent report to be presented later in the year.

 

In relation to Local Audit Reform, it was noted that there were no major updates at the present time. As reported to the Committee at its previous meeting, the Government continued to progress the steps required to establish the Local Audit Office as part of implementing the English Devolution and Empowerment Bill. Further updates would be provided to the Committee later in the year as necessary.

 

It was reported that the Authority had not undertaken any RIPA activity during the period under review, and it was recognised that such activity was rarely required

 

In respect of Whistleblowing, the Committee was required to be informed of activity under the Whistleblowing Policy as part of the monitoring arrangements in place since the policy’s adoption in July 2023. It was reported that there had been no such notifications since the Committee’s last meeting.

 

Questions by Members:

Answers:

In relation to the red?rated risks, could you provide further detail on how frequently these risks are reassessed? Additionally, are there any publicly available metrics that demonstrate how these risks are being managed over time? For instance, in the case of cyber incidents, is there data indicating how many attempted attacks have been detected or prevented?

(Richard Barrett) Yes. We undertake a formal cyber assessment that provides an evidence?based view of our current position. Ongoing monitoring is built into our regular Management Team meetings, where any emerging issues are escalated as needed. We also report to Senior Managers on a six?monthly cycle.

 

Decisions about what can be shared publicly are carefully balanced, as some information could create risk if disclosed too widely. However, sharing relevant statistics with Members internally should not present a problem, provided we remain mindful that this data should not enter the public domain.

 

I will source the relevant statistics and arrange for them to be shared, potentially through an informal session if that is the most appropriate route.

In the review of the February 2026 minutes—specifically item 23, the Building Safety Inspection Review, which I have previously emailed about—it occurred to me that although the BSR issues were successfully closed in January, there may be value in confirming that the new control arrangements are fully embedded and operating effectively.

Could the Committee consider scheduling a building control compliance review for later in 2026/27, covering areas such as site?change controls, the operations manual, outsourced plan checking, and the consultee reporting process?

Additionally, in relation to the BSR, was any of this learning shared across other service areas—for example, environmental health or the waste and recycling contract—and is there further insight to be gained from that?

 

(Richard Barrett) We can incorporate this into the recommendations, ensuring that the Committee receives further updates on the Building Control Inspection and on how learning from the process is being shared across the Council.

 

 

It was unanimously RESOLVED that:

 

(a)  the updates set out within the report (A.2) be noted;

 

(b)  following the Building Safety Inspection Review outcomes and actions reported to the meeting of the Audit Committee held on 19 February 2026, the Committee requests that a further update be provided during 2026/27, including whether there have been any opportunities to share any associated learning elsewhere within the Council ;and

 

(c)   the Committee requests Officers to further develop the revised approach to the Assurance and Risk Management Framework, as set out within the report (A.2), with the aim of presenting an updated position for consideration / adoption to the next meeting of the Committee in June 2026.

Supporting documents: